Live data from Hacker News

Some observations on the final text of the European Digital Identity framework

blog.xot.nl

111–120 of 153 posts

Re: Some observations on the final text of the European Digital Identity framework

#111
post #104

So basically: Governments are being given authority to create dodgey certificates, Browsers can't take it down if discovered unless they have evidence it's being used and will be harmful, and Browsers need to advise and wait for the requisite approval [of authorities] for when the browser can take it down (i.e. the authorities can decide how long it stays up). Or am I missing something?

[flagged]

It would be impossible for them to force me to blindly accept a government issued ID card as true, and it would be insane for me to comply with such a demand. The same is true here, I won't run a browser or OS that complies with these regulations and as far as I can tell, they can't realistically make me.

The problem is if companies like Apple and Microsoft that make proprietary operating systems are forced to comply by the threat of import bans, etc. That would make their less technologically sophisticated customers vulnerable to completely unnecessary risks. The EU might not think the risks are unnecessary because they gain "sovereignty", but that only helps the EU and their member states, not 99.999% of the people who live in their territory.

Ultimately, I don't think this will be implemented. They can scream "sovereignty" as much as they want, but everyone else has an incentive to resist, and it would be even more harmful to their perception of sovereignty if both Microsoft and Apple say no and the EU faces the choice of either banning 99% of computers on the consumer market (and still be unable to force the remaining open source alternatives to meaningfully comply) or backing down to foreign organizations after a public confrontation.

Re: Some observations on the final text of the European Digital Identity framework

#112
post #71

Earlier quoted context omitted.

Currently the default trust list in your browser is solely decided by your browser. More specifically there's an organization called the CA/Browser Forum where all the browser vendors are. If you want to become a CA today, you go to the Forum, submit your proposal, and then the browser vendors decide whether or not you're trustworthy. If a CA misissues certificates or otherwise screws up security, that evidence goes…

> eIDAS changes this by, effectively, creating a special EU government analogue to the CA/Browser Forum. All browser developers in the EU have to trust eIDAS's CAs. This is a transfer of power from a voluntary industry consortium to appointed EU technocrats. The flipside is that while it may be a "voluntary consortium", all major browsers are developed by entities based in the US, that are therefore subject to Nation…

EU governments will be even more subject to pressure from the US. I don't understand how anyone could doubt they will comply with every request from the US government.

The difference is that the current decision makers only have power because other people trust them voluntarily. That makes them accountable, and it means a whistleblower can do much more to limit the damage by leaking the fact they are giving after to US pressure.

A government can impose its will by force, so it is much less accountable and doesn't have to worry about the consequences of its decisions nearly as much. There is nothing I can realistically do if I object to a decision by a government unless I'm a large political donor because governments don't need my consent to operate.

Re: Some observations on the final text of the European Digital Identity framework

#113
post #104

Earlier quoted context omitted.

[flagged]

This is an interesting point of view. This also pertains to root certificates in browsers however. Would a better way be not to setup a body to monitor certificates issued to police certificates for their own CA and ensure any offending certificate is immediately removed and to bring in laws to penalise the offending CA. Instead they're prying a new threat vector open wide.

Yeah, I'm not sure if I fully agree with the method here either - it feels like it was helped by law enforcement a bit too much.

But I did want to make a point about why such paragraph exists and why it's not acceptable for EU to delegate CA policing to non-governmental industry bodies.

Re: Some observations on the final text of the European Digital Identity framework

#114

Earlier quoted context omitted.

A reasonable concern here is that power is transfered from subject matter experts to technocrats with a poor track record of making technical decisions. Some recent examples of EU tech debacles include Quaero, Galileo, Gaia-X, Ariane 6.

On the other hand, the technocrats are beholden to actual elected officials, instead of the current situation where a group of random people selected by private companies coordinate their work by consensus without much formal structure and the members are beholden to nobody by their company boss.

And those elected officials are beholden to the highest bidder. In the current system, the people who make CA decisions acquired that power voluntarily and seem to have acted benevolently in the past, that's way more than you can say about government officials.

The current voluntary system is also very open, and anyone can get involved and participate to a much larger extent than people realistically can in an electoral democracy. To me, the voluntary system seems to be better and safer for everyone who doesn't have a very large amount of money to throw at elections.

Re: Some observations on the final text of the European Digital Identity framework

#115
post #91

Earlier quoted context omitted.

A reasonable concern here is that power is transfered from subject matter experts to technocrats with a poor track record of making technical decisions. Some recent examples of EU tech debacles include Quaero, Galileo, Gaia-X, Ariane 6.

And big EU tech successes like GDPR, DMA and many others. What's your point? This is about identity regulation, not random rockets.

I certainly wouldn't call those successes.

Re: Some observations on the final text of the European Digital Identity framework

#116
post #104

Earlier quoted context omitted.

[flagged]

It would be impossible for them to force me to blindly accept a government issued ID card as true, and it would be insane for me to comply with such a demand. The same is true here, I won't run a browser or OS that complies with these regulations and as far as I can tell, they can't realistically make me. The problem is if companies like Apple and Microsoft that make proprietary operating systems are forced to comply…

As if they would say no.

Re: Some observations on the final text of the European Digital Identity framework

#117
post #3

Weasel words. "Running additional security checks" is certainly going to mean the UI checks, not anything on the backend. Cookie banners happened because US devs didn't steelman EU regs. Petty territorial behavior. This looks like someone trying not to learn their lesson.

All of the EU's own websites have cookie banners. Everyone has cookie banners. The problem here is the law, not the companies.

Re: Some observations on the final text of the European Digital Identity framework

#118
post #104

Earlier quoted context omitted.

[flagged]

It would be impossible for them to force me to blindly accept a government issued ID card as true, and it would be insane for me to comply with such a demand. The same is true here, I won't run a browser or OS that complies with these regulations and as far as I can tell, they can't realistically make me. The problem is if companies like Apple and Microsoft that make proprietary operating systems are forced to comply…

They could comply and treat them like self signed certificates with a click through screen.

"This website's certificate is issued by CA. Are you sure you want to proceed?"

Re: Some observations on the final text of the European Digital Identity framework

#119

So basically: Governments are being given authority to create dodgey certificates, Browsers can't take it down if discovered unless they have evidence it's being used and will be harmful, and Browsers need to advise and wait for the requisite approval [of authorities] for when the browser can take it down (i.e. the authorities can decide how long it stays up). Or am I missing something?

spot-on. it helps to recall that ETSI, despite being some opaque standards org is made of people[1] like you and me (many not in Europe) who helped draft this abomination of a standard. This is disguised as digital identity but the interest groups are mostly law-enforcement, and the same crowd that is pushing "chatcontrol", and "regulating cryptography". This "secret list" of experts is here[1]. And here is Tanja Lan…

Nice that the person from GCHQ is called Crispin.

Re: Some observations on the final text of the European Digital Identity framework

#120
post #104

Earlier quoted context omitted.

[flagged]

It would be impossible for them to force me to blindly accept a government issued ID card as true, and it would be insane for me to comply with such a demand. The same is true here, I won't run a browser or OS that complies with these regulations and as far as I can tell, they can't realistically make me. The problem is if companies like Apple and Microsoft that make proprietary operating systems are forced to comply…

Companies are going to follow the money.

Other countries will probably turn a blind eye, either:

for allies: on the proviso that the EU share the data with them.

for adversaries: a good excuse to cordon off their internal internet, which they can then monitor as they wish.

Post reply on HN